Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
2
2 months ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
26 months ago
cve-2023-3824 preview

cve-2023-3824

GitHubdadosneurais/cve-2023-3824

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

command-and-controlexploitationpayload-generation+3
0 years ago
r2rs preview

r2rs

GitHubhakkuri01/r2rs

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

command-and-controlexploitationpenetration-testing+3
13 months ago
CVE-2015-6967-EXPLOIT preview

CVE-2015-6967-EXPLOIT

GitHubinnocentx0/cve-2015-6967-exploit

CVE-2015-6967 PoC Exploit

educationexploitationpayload-generation+3
1 year ago
Armor preview

Armor

GitHubtokyoneon/armor

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

encryption-decryption-toolspayload-developmentpayload-generation+3
2777 years ago
SharpProxyLogon preview

SharpProxyLogon

GitHubflangvik/sharpproxylogon

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

exploitationpayload-developmentpost-exploitation+3
2475 years ago
ASPX_WebShell_COFFLoader preview

ASPX_WebShell_COFFLoader

GitHubepotseluevskaya/aspx_webshell_coffloader

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

command-and-controlpayload-developmentpenetration-testing+3
1366 months ago
CVE-2019-18935-memShell preview

CVE-2019-18935-memShell

GitHubdust-life/cve-2019-18935-memshell

C++ memshell DLL generator for CVE-2019-18935, enabling in-memory web shell deployment via Telerik UI deserialization with Assembly.Load and IJW…

exploitationpayload-developmentpenetration-testing+2
121 year ago
Flangvik preview

Flangvik

GitHub1342486672/flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

exploitationpayload-generationpenetration-testing+2
4 years ago
Flangvik preview

Flangvik

GitHubyaoxiaoangry3/flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

exploitationpenetration-testingshellcode+2
4 years ago
CVE-2023-4220-exploit preview

CVE-2023-4220-exploit

GitHubpr1or95/cve-2023-4220-exploit

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

exploitationpayload-generationpenetration-testing+3
11 year ago
wshlient preview

wshlient

GitHubgildasio/wshlient

A simple tool to interact with web shells and command injection vulnerabilities

command-and-controlpenetration-testingshellcode+1
371 year ago
CVE-2025-32206 preview

CVE-2025-32206

GitHubnxploited/cve-2025-32206

WordPress Processing Projects Plugin <= 1.0.2 is vulnerable to Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
21 year ago
CVE-2019-16278-Nostromo-1.9.6-RCE preview

CVE-2019-16278-Nostromo-1.9.6-RCE

GitHubcancela24/cve-2019-16278-nostromo-1.9.6-rce

Exploit for CVE-2019-16278 targeting Nostromo Web Server 1.9.6, achieving remote code execution via directory traversal. Uses pwntools to deliver a…

educationexploitationpayload-generation+3
11 year ago
reverse_ssh preview

reverse_ssh

GitHubnhas/reverse_ssh

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

shellcodeshellcode-generation
1.5k13 days ago
warsend preview

warsend

GitHubthewhiteh4t/warsend

Apache Tomcat Manager API WAR Shell Upload

exploitationpayload-generationpenetration-testing+3
366 years ago
WinAPRS-Exploits preview

WinAPRS-Exploits

GitHubcoalfire-research/winaprs-exploits

A collection of exploits, shellcode, and tools related to CVE-2022-24702

exploitationpayload-developmentpenetration-testing+3
94 years ago
Previous123456Next